Press "Enter" to skip to content

That’s #SketchyEtsy!

Update: Jan 4, 2023 – We made a video summarizing our research. Please watch and share!

Thank you so much for joining us in this fight.  #indiestrong!

Please sign our petition!

Late in August, Etsy rolled out a requirement that US-based sellers use a third party service, Plaid, to verify our bank accounts. Plaid has been embroiled in lawsuits for alleged user privacy violations.  The Indie Sellers Guild is fighting back.  Etsy sellers should NOT be required to share our private financial data with a sketchy service to keep getting paid.

FAQ

We aren’t sure.  The fact that this notice has gone to some, but not all, US-based sellers certainly sheds doubt on Etsy’s claim that this is an action they are required to take by law.  Perhaps they’re rolling it out in waves to troubleshoot technical issues?  Some users have reported technical difficulties which prevented access to their funds for a while due to having connected Plaid to their bank account.

If you verified your account with Plaid, and used your online banking login and password to do so, we recommend changing them (both login and password) immediately.  Depending on your bank’s terms of service, you could be in danger of losing fraud protection on your account.  For example, here is an excerpt from the TOS for Santander Bank:

You agree to: 1) keep your User ID and password secure and strictly confidential; 2) immediately notify us of any change in status, or authority, of any authorized signer on record with the bank; and 3) immediately notify us and select a new User ID or password if you believe your User ID or password may have become known to or used by an unauthorized person. The bank will have no liability to you for any unauthorized payment or transfer made using your User ID or password that occurs before you have notified us of possible unauthorized use and we have had a reasonable opportunity to act on that notice. We may suspend or cancel your use of Digital Banking without notice from you if we suspect you’re User ID or password is being used in an unauthorized or fraudulent manner.

If you used your bank routing and account number to connect, we recommend taking no action.   Users have reported losing access to their Etsy funds when they tried to disconnect accounts after the fact. Sign our petition, and make sure you’re opted into email updates!  We will keep you updated with the most current advice.

We’re still trying to figure this one out.  If you have information to share, please reach out via the contact form at the end of this page.

The only thing we’ve found for new(ish) money laundering regulations is the Anti-Money Laundering Act of 2020. With help from a partner organization, we also found a whitepaper put out by Plaid themselves, detailing what corporations should do to comply with the law.  We have no reason to believe that Plaid would misrepresent the information to their own corporate partners, and they clearly state that the law applies to new accounts only. Already-established Etsy accounts with linked bank accounts should be exempt from the new law, at least according to what Plaid themselves published.

Etsy initially stated that they will stop paying these sellers money they are owed for sales made on the platform, unless they connect their bank accounts with Plaid.

Later, we received reports of a different message replacing the first in sellers shop dashboard.

The initial threat to stop sending money owed has escalated to include shop suspension, unless sellers agree Plaid can share their private financial data.

If you are a California resident, it looks like there is a California Consumer Privacy Act (“CCPA”) which requires Plaid to delete your data on request. Please see the “Your Data Protection Rights” section of Plaid’s privacy policy for more information, and a link to an online form to request data deletion.

There does not seem to be an option for US residents outside of California to have Plaid delete their data.

No, not at the end of the first 30 days, at least according to the experiences of ISG members who were in the first wave of notices. At the end of the first 30 day timer, Etsy will stop paying you for sales made on the platform, and you will be given a second 30 day notice for shop suspension. Suspension appears to be the end result 60 days after receiving the Plaid notification, should you refuse to share your private financial data with Plaid.

The Story

Late in August of 2022, US based Etsy sellers were informed that we were required to verify our bank accounts through a third party service, Plaid.  

When this happened, users inside our Discord server reached out to warn us about Plaid’s rather sketchy past.

Plaid has been embroiled in class action lawsuits over user privacy violations. One of our Discord members was a recipient of a settlement. She reported that Plaid tricked her by creating a page that looked just like her bank’s login page, so that she entered the login and password for her bank account without thinking twice, as the page had been linked from her Venmo account.

Based on the information we had at the time, we created the images in the slideshow below, and shared them on social media to warn people.

On Etsy, (at least until recently) the default option was to give Plaid your online banking username and password to verify your account. There is a second option to give Plaid your bank account number and routing number to verify your account.

Not all US-based sellers have received this notice, but those who have must use Plaid (and agree to their end user privacy policy) to keep getting paid. Many of us are uncomfortable agreeing to this policy, for obvious reasons! Here are a few excerpts of the policy itself, taken from the page on Plaid’s website.

Information We Collect and Categories of Sources

As explained in greater detail below, depending on which of Plaid’s service you or the developer uses, Plaid may collect the following:

  • Identifiers (for example, name, email address, phone number, and username);
  • Location information (for example, timezone setting and device location);
  • Financial information (for example, financial account name and number, balance, and transaction history);

Information you provide. When you connect your financial accounts with a developer application or otherwise connect your financial accounts through Plaid, where applicable, we collect identifiers and login information required by the provider of your account, such as your username and password, or a security token. In some cases, we also collect your Social Security number, date of birth, phone number, email address, security questions and answers, and one-time password (OTP) to help verify your identity and connect your financial accounts.

Information we receive from your devices. When you use your device to connect to our services through a developer’s application, we receive identifiers and electronic network activity information about that device, including internet protocol (IP) address, timezone setting and location, device location, hardware model, operating system, which features within our services you access, browser data, and other technical information about the device. We also use cookies or similar tracking technologies to collect usage statistics and to help us provide and improve our services. You can find more information about how we use cookies and your related choices in our Cookie Policy.

When you go to take this step from within your Etsy account, you’ll see the following message:

“Plaid will never share your data without your permission”.  Quite the tricky statement.  By agreeing to Plaid’s End User Privacy policy, you are giving them permission to share your data.  With “partners”:

With our data processors and other service providers, partners, or contractors in connection with the services they perform for us or developers;

Plaid’s End User Privacy Policy also states:

We may collect, use, and share End User Information in an aggregated, de-identified, or anonymized manner (that does not identify you personally) for any purpose permitted under applicable law. This includes creating or using aggregated, de-identified, or anonymized data based on the collected information to develop new services and to facilitate research to the extent permitted under applicable law.

We are artists and creative business owners, not experts on privacy – but this sounds like it would allow advertisers to target ads to you based on your full financial history, anonymized to remove specific identifying information.  Quite the disturbing prospect!

We HIGHLY recommend reading the whole thing before you proceed, if you choose to proceed.  We also recommend that you DO NOT give your bank account username and password to Plaid. Use the option to verify with your account and routing number.

An option for filling this requirement without giving Plaid access to your main business bank account is to register a free online-only bank account, as outlined in this blog post by Kristi.

Update: 10/5 – Please file a formal complaint with the FTC

The Federal Trade Commission is a US government department that works “to ensure that our markets are open and free.” In a free market, businesses compete based on their merits, and consumers freely choose to patronize a specific business.  Being forced to sign up for Plaid – a service that we do not want – in order to keep our Etsy shops open and keep getting paid is the exact opposite of this ideal.  We believe that Etsy’s Plaid requirement violates US Antitrust Law. The exact law in question is “Tying the Sale of Two Products”:

For competitive purposes, a monopolist may use forced buying, or “tie-in” sales, to gain sales in other markets where it is not dominant and to make it more difficult for rivals in those markets to obtain sales. This may limit consumer choice for buyers wanting to purchase one (“tying”) product by forcing them to also buy a second (“tied”) product as well. Typically, the “tied” product may be a less desirable one that the buyer might not purchase unless required to do so, or may prefer to get from a different seller. If the seller offering the tied products has sufficient market power in the “tying” product, these arrangements can violate the antitrust laws.

The consumer bulletin on antitrust law includes an example:

For example, the antitrust laws likely would not permit a drug manufacturer to require customers to buy a patient monitoring system they don’t want along with the prescription drugs they do want.

Based on our research, it looks like past cases of tied sales were settled in favor of the corporation only when they could prove that the tied product was necessary, and they could not offer another option to consumers.  As Etsy already offers manual non-Plaid account verification to sellers outside the US, that does not seem to be the case here!

In any event, the FTC can sort it out and tell us for sure.

Please file a formal complaint with the FTC.  The more complaints filed, the more likely it is that they investigate this issue.  Click here for copy-paste email templates, and complete instructions.

UPDATE: 9/14/22 – A Partial victory

We saw this tweet in our notifications on 9/14, and thought we might be about to declare victory on this project!

https://twitter.com/whimziequiltz/status/1569682260118634496?s=20&t=tJnExPmYVPTkntPX8_6erw

Combined with another change (a green “verified” label) inside accounts not yet verified, it looked really hopeful that Etsy was working on another option for us:

We reached out to the user on Twitter to be certain the option they had received was non-Plaid – and sadly it was still Plaid-based.

But Etsy has made the option to verify without giving Plaid your bank login and password easier to find, and that is a positive step.

Let’s keep the pressure on until they offer us a non-Plaid option!

UPDATE: 9/17 – It’s almost time for the press release

Yesterday, we asked everyone that had signed our petition to reach out to Etsy support to ask for a safe, non-Plaid option to verify, and make note of what Etsy said in response.

Those of us who were first to reach out got the exact type of response expected.  Zero solutions, and a promise to forward our concerns to Etsy.  But then, more and more of us reached out.  And something unexpected happened.

According to reports from multiple people who reached out to Etsy support between the hours of 10AM EST and about 1PM EST, Etsy started responding that they were assigning a “special team” to the project, and to expect an email with a manual, non-Plaid option to verify their bank account.  But it looks like that was sadly short lived.  Etsy hasn’t lived up to its promise to send the email to any of those people (we will update you if that changes), and now, once again, users that reach out are told that we have no choice but to give Plaid full access to our private financial information to be able to keep our shops open.

But we’re only just getting started on this project.

The next step

We have a press release about Plaid which we plan to send to our media contacts on Monday.  Here’s a preview:

We’d like to say that the petition has gotten “thousands of signatures in only 10 days”.  It’s not far away from that goal right now?  Can you help?  Please sign and share!

Update: 9/20 – The press release is ready!

We reached out to our media contacts about this, but the ones most eager to cover the story have been local channels! So we really need your help getting the word out!  Please click here for instructions on reaching out to your local media, and a pdf download of the press release about Plaid.

Spread the Word

Please help us spread the word! Feel free to download and use the images from the slideshow in “The Story” section above, or here are a couple of single-page versions you can use to spread the word.

Here are copy-paste text blurbs with a link to the petition:

Please sign our petition to stop Etsy from violating our privacy rights as Etsy sellers! https://chng.it/khKrWb4ftH That’s #SketchyEtsy! #indiesellersguild #privacy #safetyfirst
Please protect Etsy seller privacy rights!  Sign our petition! https://chng.it/khKrWb4ftH That’s #SketchyEtsy! #indiesellersguild #privacy #safetyfirst
Are you still holding out on that sketchy Plaid bank verification for your Etsy shop?  Sign the petition to fight back! https://chng.it/khKrWb4ftH #SketchyEtsy #indiesellersguild #privacy #safetyfirst

And please tell everyone you know about the ISG. The more members we have, the more likely it becomes that we receive advance notice when Etsy (and other tech platforms) are planning to take sketchy actions like this one. More time to organize equals a better chance of success at fighting back!